Pickle Deserialization RCE via Model Upload Endpoint
Link: https://www.ratctf.com/challenges/synapse-lab
This challenge revolves around a classic but still heavily abused primitive: unsafe Python pickle deserialization exposed through a model upload API
noob6t5.hashnode.dev4 min read